Account & security

Security

Protect your account and understand how your data is handled.

Two-factor authentication

Turn on two-factor authentication (2FA) from Settings → Profile → Account security. Once enabled, you'll enter a code from your authenticator app when you sign in, in addition to your password.

Turn this on if you have admin access. An Inverity admin account can reach the credentials that grant access to your CMS or DAM. A compromised password on a view-only account exposes savings statistics; a compromised password on an admin account is a route into your content platform.

How your data is handled

Your credentials are encrypted. Tokens you provide to connect a source are stored encrypted and used only to access the assets you point Inverity at. See Tokens and permissions.

Your originals are protected. Inverity only replaces a file with a smaller, quality-checked version, and DAM masters are kept as new versions rather than overwritten. There is no code path that deletes an asset from your platform. See How write-back works.

Your media is yours. Inverity processes your assets to optimize them. See our privacy policy at inverity.ai for full details on data handling and retention, and Data and privacy for how this works day to day.

Practical hardening

  • Scope tokens narrowly. Grant media read and write, nothing else, where your platform allows it.
  • Use service accounts for connectors rather than a named person's login, so a departure doesn't break your integration.
  • Keep the admin list short. See Team and roles.
  • Remove people promptly when they leave.
  • Rotate a token if it's ever exposed — in a ticket, a chat message, or a screenshot. Revoke it in your platform, create a new one, and update the connector.

Reporting a security issue

Email security@inverity.ai.

If you believe an account has been compromised, change the password and enable 2FA immediately, then rotate the tokens for every connected source and email security@inverity.ai with what you observed and when.

If a connector token leaks

Revoke it in your own platform first — that's the action that actually stops the access, and it takes effect immediately. Removing the connector in Inverity is the second step, not the first. The connector will report an authorization error in the meantime, which is expected.

Previous
Profile and sign-in